st records
29 published records for vendor st.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-191 Integer Underflow (Wrap or Wraparound)4
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-459 Incomplete Cleanup2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
The weakness classes this vendor ships most often: where to look.
CWEAll records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-14236No exploit | On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a softst · stm32l0 firmware · CWE-863 | Critical9.8 | — | 2.3% | Sep 12, 2019 |
39Monitor | CVE-2024-45064No exploit | A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-119 | Critical9.8 | — | 1.1% | Apr 2, 2025 |
39Monitor | CVE-2021-42553No exploit | STM32 USB Host Library Buffer Overflowst · stm32 mw usb host · CWE-120 | Critical9.8 | — | 1.1% | Oct 21, 2022 |
31Monitor | CVE-2020-8004Proof of concept | STMicroelectronics STM32F1 devices have Incorrect Access Control.st · stm32f1 firmware | High7.5 | — | 3.0% | Apr 6, 2020 |
30Monitor | CVE-2024-50385No exploit | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-459 | High7.5 | — | 0.8% | Apr 2, 2025 |
30Monitor | CVE-2024-50384No exploit | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-459 | High7.5 | — | 0.8% | Apr 2, 2025 |
30Monitor | CVE-2024-50595No exploit | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-191 | High7.5 | — | 0.8% | Apr 2, 2025 |
30Monitor | CVE-2024-50597No exploit | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-191 | High7.5 | — | 0.8% | Apr 2, 2025 |
30Monitor | CVE-2024-50596No exploit | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-191 | High7.5 | — | 0.8% | Apr 2, 2025 |
30Monitor | CVE-2024-50594No exploit | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-191 | High7.5 | — | 0.8% | Apr 2, 2025 |
30Monitor | CVE-2023-50096No exploit | STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to tst · x-cube-safea1 · CWE-120 | High7.5 | — | 0.6% | Jan 1, 2024 |
28Monitor | CVE-2020-27212No exploit | STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control.st · stm32cubel4 firmware · CWE-74 | High7.0 | — | 0.3% | May 21, 2021 |
27Monitor | CVE-2021-34262No exploit | A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackst · stm32cube middleware · CWE-120 | Medium6.8 | — | 0.5% | Jul 22, 2021 |
27Monitor | CVE-2021-34259No exploit | A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attacst · stm32cube middleware · CWE-120 | Medium6.8 | — | 0.5% | Jul 22, 2021 |
27Monitor | CVE-2021-34260No exploit | A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allowsst · stm32cube middleware · CWE-120 | Medium6.8 | — | 0.5% | Jul 22, 2021 |
27Monitor | CVE-2020-13466No exploit | STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specificst · stm32f103 firmware | Medium6.8 | — | 0.4% | Aug 31, 2020 |
26Monitor | CVE-2019-19192No exploit | The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecust · wb55 · CWE-20 | Medium6.5 | — | 1.0% | Feb 12, 2020 |
26Monitor | CVE-2019-14238No exploit | On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with ast · stm32l0 firmware · CWE-287 | Medium6.6 | — | 0.4% | Sep 24, 2019 |
25Monitor | CVE-2003-0392No exploit | Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS drst · ftp service | Medium6.4 | — | 1.4% | Jul 2, 2003 |
24Monitor | CVE-2019-16863No exploit | STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing atst · st33tphf2espi firmware · CWE-203 | Medium5.9 | — | 3.4% | Nov 13, 2019 |
24Monitor | CVE-2021-29414No exploit | STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.st · stm32cubel4 firmware · CWE-74 | Medium6.1 | — | 0.3% | May 21, 2021 |
24Monitor | CVE-2021-43392No exploit | STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets.st · j-safe3 firmware · CWE-347 | Medium6.2 | — | 0.2% | Mar 4, 2022 |
24Monitor | CVE-2021-43393No exploit | STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification.st · stsafe-j firmware · CWE-347 | Medium6.2 | — | 0.2% | Mar 4, 2022 |
23Monitor | CVE-2020-20949No exploit | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).st · stm32cubef0 · CWE-327 | Medium5.9 | — | 0.9% | Jan 20, 2021 |
22Monitor | CVE-2023-36629No exploit | The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.st · st54-android-packages-apps-nfc · CWE-125 | Medium5.5 | — | 0.4% | Jan 8, 2024 |
- CVE-2019-1423640Plan
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a soft
CriticalCVSS 9.8No exploitEPSS 2%st · stm32l0 firmwareSep 12, 2019
- CVE-2024-4506439Monitor
A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
CriticalCVSS 9.8No exploitEPSS 1%st · x-cube-azrt-h7rsApr 2, 2025
- CVE-2021-4255339Monitor
STM32 USB Host Library Buffer Overflow
CriticalCVSS 9.8No exploitEPSS 1%st · stm32 mw usb hostOct 21, 2022
- CVE-2020-800431Monitor
STMicroelectronics STM32F1 devices have Incorrect Access Control.
HighCVSS 7.5Proof of conceptEPSS 3%st · stm32f1 firmwareApr 6, 2020
- CVE-2024-5038530Monitor
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
HighCVSS 7.5No exploitEPSS 1%st · x-cube-azrt-h7rsApr 2, 2025
- CVE-2024-5038430Monitor
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
HighCVSS 7.5No exploitEPSS 1%st · x-cube-azrt-h7rsApr 2, 2025
- CVE-2024-5059530Monitor
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
HighCVSS 7.5No exploitEPSS 1%st · x-cube-azrt-h7rsApr 2, 2025
- CVE-2024-5059730Monitor
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
HighCVSS 7.5No exploitEPSS 1%st · x-cube-azrt-h7rsApr 2, 2025
- CVE-2024-5059630Monitor
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
HighCVSS 7.5No exploitEPSS 1%st · x-cube-azrt-h7rsApr 2, 2025
- CVE-2024-5059430Monitor
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
HighCVSS 7.5No exploitEPSS 1%st · x-cube-azrt-h7rsApr 2, 2025
- CVE-2023-5009630Monitor
STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to t
HighCVSS 7.5No exploitEPSS 1%st · x-cube-safea1Jan 1, 2024
- CVE-2020-2721228Monitor
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control.
HighCVSS 7.0No exploitEPSS 0%st · stm32cubel4 firmwareMay 21, 2021
- CVE-2021-3426227Monitor
A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attack
MediumCVSS 6.8No exploitEPSS 0%st · stm32cube middlewareJul 22, 2021
- CVE-2021-3425927Monitor
A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attac
MediumCVSS 6.8No exploitEPSS 0%st · stm32cube middlewareJul 22, 2021
- CVE-2021-3426027Monitor
A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows
MediumCVSS 6.8No exploitEPSS 0%st · stm32cube middlewareJul 22, 2021
- CVE-2020-1346627Monitor
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific
MediumCVSS 6.8No exploitEPSS 0%st · stm32f103 firmwareAug 31, 2020
- CVE-2019-1919226Monitor
The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecu
MediumCVSS 6.5No exploitEPSS 1%st · wb55Feb 12, 2020
- CVE-2019-1423826Monitor
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a
MediumCVSS 6.6No exploitEPSS 0%st · stm32l0 firmwareSep 24, 2019
- CVE-2003-039225Monitor
Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS dr
MediumCVSS 6.4No exploitEPSS 1%st · ftp serviceJul 2, 2003
- CVE-2019-1686324Monitor
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing at
MediumCVSS 5.9No exploitEPSS 3%st · st33tphf2espi firmwareNov 13, 2019
- CVE-2021-2941424Monitor
STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.
MediumCVSS 6.1No exploitEPSS 0%st · stm32cubel4 firmwareMay 21, 2021
- CVE-2021-4339224Monitor
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets.
MediumCVSS 6.2No exploitEPSS 0%st · j-safe3 firmwareMar 4, 2022
- CVE-2021-4339324Monitor
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification.
MediumCVSS 6.2No exploitEPSS 0%st · stsafe-j firmwareMar 4, 2022
- CVE-2020-2094923Monitor
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).
MediumCVSS 5.9No exploitEPSS 1%st · stm32cubef0Jan 20, 2021
- CVE-2023-3662922Monitor
The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
MediumCVSS 5.5No exploitEPSS 0%st · st54-android-packages-apps-nfcJan 8, 2024